← Back to Feed

Inductive Automation Ignition

CVE-2026-77393

September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77393 In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected. View CVE Details Affected Products Inductive Automation Ignition Vendor:Inductive Automation Product Version:Inductive Automation Ignition: <=8.1.53 Product Status:known_affected Remediations MitigationInductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability. MitigationInductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security...

Key Takeaways

  • CISA published an advisory for Inductive Automation Ignition urging users to apply vendor patches and mitigations.
  • The advisory covers 1 vulnerabilities in Inductive Automation Ignition that require immediate patching.
  • Active exploitation of vulnerabilities in Inductive Automation Ignition has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee